#rbac
Unit 42 releases OperTraitor, an LLM-powered tool to audit Kubernetes operators for excessive RBAC permissions. Many operators on OperatorHub found to be overly permissive, creating silent backdoors. #Kubernetes #DevSecOps #RBAC #CloudSecurity

🌐 cyber[.]netsecops[.]io
New
Unit 42 researchers release OperTraitor, an open-source tool to audit excessive RBAC permissions in Kubernetes operators, uncovering significant supply...
cyber.netsecops.io
September 29, 2026 at 2:00 PM
@paloaltonetworks.com
Overprivileged operators can expose cluster secrets and enable autonomous AI-driven compromise.
-
IOCs: CVE-2026-6389
-
#Kubernetes #RBAC #ThreatIntel
Kubernetes Operator RBAC Risks
unit42.paloaltonetworks.com
September 29, 2026 at 12:52 PM
OperTraitors: How Kubernetes Operators Betray Your Security Posture

This article correctly identifies RBAC as the foundational weakness, but it risks over-attributing the severity of the threat to the tooling itself rather than the systemic failure in vendor lifecycle management. If the primary…
huntaegis.com
September 29, 2026 at 11:24 AM
📦 monkeyscloud/monkeyslegion-auth 2.2.0

High-performance authentication & authorization: multi-guard, JWT, RBAC, OAuth, 2FA, API keys, passkeys

🔗 https://github.com/MonkeysCloud/MonkeysLegion-Auth
September 29, 2026 at 1:37 AM
📦 wnikk/laravel-access-rules 3.3.4

Fast access control for Laravel: RBAC with roles, groups and unlimited inheritance, extended to ABAC: conditions on any model, its relations and aggregates, with list filtering.

🔗 https://github.com/wnikk/laravel-access-rules
September 28, 2026 at 4:27 PM
Can you name every principal holding Contributor in five or more of your subscriptions? That repetition is rarely intent. It's bulk provisioning, and it hands one compromised identity reach across all of them.

Learn more at getstratolens.com
September 28, 2026 at 4:00 PM
The RBAC gap is where these PoCs die. Two things that held up for us: the MCP server holds only a read-only ES API key scoped to the log indices (no _delete_by_query, no cluster privileges), and every tool clamps size + time range server-side so an agent can't pull 90 days of logs.
September 28, 2026 at 9:36 AM
Full build: inventory as code, an LLM that only picks from 8 diagnoses, RBAC with no create or delete on Secrets, cmctl renew capped at 1 per cert per 24h.
https://devtocash.com/blog/2026-09-28-tls-certificate-expiry-agent-cert-manager-renewal-failures
#Kubernetes #SRE #DevOps
Build a TLS Certificate Expiry Agent: Catch cert-manager Renewal Failures, Unmanaged Secrets, and Stale Certs Before the Outage
Build a TLS certificate expiry agent for Kubernetes: diagnose cert-manager renewal failures, unmanaged TLS secrets and stale served certs before they expire.
devtocash.com
September 28, 2026 at 1:17 AM
📦 jncarter123/soundboard v2.3.0

A multi-app control panel for Laravel Reverb: database-backed apps, live and historical metrics, RBAC, and an API.

🔗 https://github.com/jncarter123/soundboard
September 27, 2026 at 6:59 PM
“Managing Kubernetes RBAC manually is a path to burnout.”

In this episode of 🌩️Thunder, Saim Safdar, CNCF Ambassador and host of the Cloud Native Podcast, explains how Paralus centralizes Kubernetes access management acr... https://whitneylee.com/2026/09/27/managing-kubernetes-rbac-manually-is.html
September 27, 2026 at 5:26 PM
📦 up2dev/rivet v2.0.0

A convention-based CRUD/RBAC foundation for building REST APIs with Laravel

🔗 https://github.com/up2dev/rivet
September 27, 2026 at 4:59 PM
📦 semitexa/rbac 2026.09.27.0404

Semitexa RBAC - role-based access control with roles, grants, and permission assignment

🔗 https://github.com/semitexa/semitexa-rbac
September 27, 2026 at 12:59 PM
📦 up2dev/rivet v1.3.1

A convention-based CRUD/RBAC foundation for building REST APIs with Laravel

🔗 https://github.com/up2dev/rivet
September 27, 2026 at 11:59 AM
Key takeaway: mTLS between services sounds comprehensive until you realize the service accounts issuing the certificates have overly broad RBAC. #DevSecOps
September 27, 2026 at 11:02 AM
The framing that clicked for me: the IDP is the right place to put an agent's guardrails. If it can only act through the same golden-path templates and PR flow developers use, its blast radius is bounded by construction, and no one has to invent a separate RBAC story just for the agent.
September 27, 2026 at 9:34 AM
Kill switch rule: FAIL CLOSED.

API server degraded? RBAC changed? Namespace gone? The agent cannot read the flag, so it behaves as paused.

An agent that keeps mutating because its safety flag was unreachable has a safety flag in name only. And cache it for seconds, not minutes.
September 27, 2026 at 1:15 AM
Today's GitHub Trending: paperclip manages agents, reverse-skill routes skills, openbao handles secrets. But who governs which agent role can call which skill version? iflytek/skillhub fills that gap: self-hosted skill registry with RBAC, versioning, and audit logs. #AgentGovernance https://github.c
September 26, 2026 at 11:58 PM
my coworker would just send prompts like "add roles and rbac to every feature in this app. ultracode xxhigh fable 5" and then play mobile games at his desk
September 26, 2026 at 9:32 PM
📦 jncarter123/soundboard v2.2.0

A multi-app control panel for Laravel Reverb: database-backed apps, live and historical metrics, RBAC, and an API.

🔗 https://github.com/jncarter123/soundboard
September 26, 2026 at 6:59 PM
Pull the list of Owner and User Access Administrator assignments in your tenant right now. The ones nobody has exercised in months are still fully live, standing access left over from a migration that ended.

Learn more at getstratolens.com
September 26, 2026 at 4:00 PM
The issue has a ValidatingAdmissionPolicy we ran on a v1.37 apiserver that reserves all of it for one platform group. Crossplane's RBAC manager and Argo CD's controller need exemptions.

Links:
- kubernetes.io/docs/refere...
- kep.k8s.io/5284

podostack.com/p/issue-036... 🍇
PodGroup, skopeo, and the RBAC verb that skips escalation checks
Gang scheduling that ships switched off, a resize EBS refuses while optimizing, three ways to copy an image index, and the RBAC check that escalate turns off
podostack.com
September 26, 2026 at 1:56 PM